Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-99679.6 CRI15.2%
——5Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)38dCVE-2026-3281—15.2%
——5——CVE-2026-116808.8 HIG15.2%
——5Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)36dCVE-2025-11215—15.2%
——5——CVE-2025-52616—15.2%
——5——CVE-2026-99618.8 HIG15.2%
——5Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)38dCVE-2026-28687—15.2%
——5——CVE-2026-98869.6 CRI15.2%
——5Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)38dCVE-2024-37654—15.2%
——5——CVE-2023-50366—15.2%
——5——CVE-2026-101686.3 MED15.2%
——5A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The manipulation of the argument param1 leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.37dCVE-2025-49560—15.2%
——5——CVE-2022-32481—15.2%
——5——CVE-2026-5282—15.2%
——5——CVE-2021-3719—15.2%
——5——CVE-2024-58109—15.2%
——5——CVE-2022-50764—15.2%
——5——CVE-2024-26949—15.2%
——5——CVE-2023-52746—15.2%
——5——CVE-2026-99658.8 HIG15.2%
——5Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)38dCVE-2026-16309—15.2%
——5——CVE-2025-55649—15.2%
——5——CVE-2026-355414.2 MED15.2%
——5An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.34dCVE-2025-54754—15.2%
——5——CVE-2026-42439—15.2%
——5——CVE-2025-55643—15.2%
——5——CVE-2021-28099—15.2%
——5——CVE-2026-563595.4 MED15.2%
——5n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges.50dCVE-2026-605798.0 HIG15.2%
——5Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).28dCVE-2026-116748.8 HIG15.2%
——5Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)36dCVE-2024-58110—15.2%
——5——CVE-2025-25526—15.2%
——5——CVE-2026-52715—15.2%
——5——CVE-2026-56358—15.2%
——5——CVE-2024-26693—15.2%
——5——CVE-2026-98769.6 CRI15.2%
——5Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)38dCVE-2024-47353—15.2%
——5——CVE-2023-36748—15.2%
——5——CVE-2025-20719—15.2%
——5——CVE-2025-399439.4 CRI15.2%
——5In the Linux kernel, the following vulnerability has been resolved:
ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer
If data_offset and data_length of smb_direct_data_transfer struct are
invalid, out of bounds issue could happen.
This patch validate data_offset and data_length field in recv_done.29d